Blog Framework Contact Us
RECON INITIAL ACCESS LATERAL MOVEMENT OBJECTIVE
Adversary simulation

Red team assessment

A red team assessment does not ask how many weaknesses are present in your network. It asks whether you would notice an intruder, and whether you could stop one before they reach what matters most.

A different question, answered honestly

A penetration test answers a controls question. Give it a scope, and senior penetration testers find as many exploitable weaknesses in that scope as the time allows. That is the right test when you need to know where your systems are soft and fix them. It is thorough by design, and it is loud: the goal is coverage, so the team makes no effort to stay hidden.

A red team assessment starts from an objective instead. We agree a single goal that matters to the business, then work towards it the way a real intruder would, quietly and patiently, across whatever path the environment actually offers. Along the way we are not only trying to get in. We are watching to see whether your monitoring notices, whether an alert fires, and whether anyone acts on it. The finding is not a list of bugs. It is an honest answer to the question every board eventually asks: if someone were already inside, would we know?

Chess pieces representing the objective-driven strategy of a red team assessment

Two tests, two different jobs

A penetration test

  • Works to an agreed scope and aims for wide coverage
  • Finds and proves as many exploitable weaknesses as the time allows
  • Runs openly; the defenders usually know it is happening
  • Best first test for finding and fixing technical gaps

A red team assessment

  • Works to one agreed objective.
  • Stays stealthy and patient; the way a real attacker does
  • Tests detection and response, not only the presence of flaws
  • Best once monitoring and a security team are in place

We agree on the finish line before we start

Every engagement is built around an objective you approve in advance. Common goals for Nigerian financial and enterprise clients include the three below.

// GOAL 01

Reach the payment system

Demonstrate, without moving a single naira, that an attacker could reach the system that initiates payments or transfers. Proof of access is captured.

// GOAL 02

Exfiltrate a marked dataset

Locate and safely copy a file or dataset we agree and mark beforehand, standing in for customer or patient records. The marker proves access without exposing real data outside your environment.

// GOAL 03

Obtain domain control

Gain domain administrator control of the internal network from a realistic starting point. Full control of identity is the goal most attacks ultimately chase, so it is a clear test of the whole chain.

Six phases

01

Reconnaissance

We map what an outsider can learn about you: exposed services, staff on public platforms, leaked credentials, third parties, and the shape of your perimeter. This is quiet work, done before any of your systems is touched.

02

Initial access

We get a foothold, most often through a targeted phishing message to an individual or through an exposed service. The route we use is one a real attacker would find.

03

Persistence

We establish a way to keep our foothold across reboots and lockouts, the way an intruder would settle in for a long stay. This is also the first real test of whether your security tools raise a flag.

04

Lateral movement

From that first computer, we move through the network towards the objective, collecting credentials, pivoting between systems, and escalating privilege where the environment lets us. 

05

Objective

We reach the agreed goal: the payment system, the marked dataset, or domain control. This is the moment that answers the business question, and it is the point at which the engagement has proved its case.

06

Safe evidence capture

We record proof of reaching the objective.

Realistic, but never reckless

Simulating a real attacker does not mean behaving like one. Before any work begins we agree written rules of engagement with named contacts on both sides, and the team operates under a signed authorization, the get-out-of-jail letter that every operator carries. It states who authorized the work and confirms the activity is sanctioned, so nobody testing on your behalf is exposed if a curious administrator or the police ask questions.

Destructive actions are ruled out from the start. We do not delete data, disrupt trading or service, or move more money than is needed to demonstrate impact. Information about the engagement is limited: the fewer people who know the test is running, the more honest the answer about detection, so we work with a small, trusted circle on your end who can pause any action immediately. 

A secured door representing the tight authorization and rules of engagement in a red team assessment

A timeline of what we did against what you saw

The value of a red team assessment is in the comparison. We lay our actions, beside what your monitoring recorded and your team acted on. The gaps between the two being the most important areas to work on.

Where detection was missing entirely, and where an alert fired but went unread
How long the intrusion ran before anyone noticed
Which of our steps should have been caught by existing tooling
How the response held up once the team did engage
The specific logs, rules, and playbooks worth changing first
A shared debrief that walks your defenders through the whole path

Most organizations should start with a penetration test

A red team assessment is not the first test to buy. If your perimeter and internal systems have never been examined, a red team will simply confirm that the obvious doors are open, which a cheaper, broader test would have shown you faster. Start with a penetration testing engagement to find and close those gaps. Come to a red team once you have monitoring, a security team, and a genuine wish to know how they perform under a realistic attack. If you are still weighing who should carry out that testing, our note on who actually tests your network is a useful starting point. For firms with a broader compliance driver, our vulnerability assessment and penetration testing services cover the combined scope.

What you receive at the end

Every finding is verified by hand with proof of exploit, and a retest of fixed issues is part of the engagement. Our approach maps to recognized standards, set out in full on our testing methodology page.

An attack narrative telling the story of the engagement
A step-by-step timeline mapped against your detections 
Technical findings with POC and reproduction details
A prioritized remediation plan your engineers can work from
An executive summary written for non-technical executives 
A retest of fixed findings, included in the engagement

Red team assessment questions, answered

How is a red team assessment different from a penetration test?

A penetration test answers a controls question: within an agreed scope, how many weaknesses can be exploited. A red team assessment is objective-driven and stealthy. It starts with one agreed goal and tests whether your team would detect and stop an intruder working inside your environment. It measures detection and response, not just the presence of flaws.

Do we need a penetration test first?

Usually, yes. If your systems have never been tested, a penetration test finds and fixes the obvious weaknesses. A red team assessment is most useful once a security team and monitoring are in place, because its purpose is to test how well they detect and respond under realistic attack conditions.

Will it disrupt our operations?

No. Destructive actions are ruled out in the rules of engagement before work begins. The team operates under a signed authorization, avoids anything that could interrupt service, and captures proof of reaching each objective. Named contacts on both sides can pause any action at once.

What does it show that scanning cannot?

A timeline of what the attacker actually did against what your defenders saw. It shows where detection was missing, how long an intrusion went unnoticed, and how the response held up once an alert fired.

Find out whether you would see us coming

Tell us the one thing you most need to protect, and we will scope a red team assessment around it, safely and on your terms.

Request a consultation